<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When setting up HA from a stand-alone...how should I configure LAN ports on the switch? What state are links on the passive node? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1221978#M123403</link>
    <description>&lt;P&gt;This is a good doc on HA best practices.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5ZCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5ZCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to HA Timer Settings, most people use Recommended, but you want faster failover choose Aggressive.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would definitely configure Link Monitoring.&amp;nbsp; I would only configure Path Monitoring if you have redundant switches toward the ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT:&amp;nbsp; No, there is nothing else you would do on the switch.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2025 22:35:20 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2025-02-26T22:35:20Z</dc:date>
    <item>
      <title>When setting up HA from a stand-alone...how should I configure LAN ports on the switch? What state are links on the passive node?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1221810#M123384</link>
      <description>&lt;DIV class="text-neutral-content"&gt;
&lt;DIV class="mb-sm  mb-xs px-md xs:px-0 overflow-hidden" data-post-click-location="text-body"&gt;
&lt;DIV id="t3_1itkwei-post-rtjson-content" class="md text-14" style="--emote-size: 20px;"&gt;
&lt;P&gt;I have a standalone PA-440 that I am in the process of moving to HA. I have all the wiring done with ISP1 and ISP2 broken out and going to the same ports on each of the 440s. That part all seems fine. I have all the licenses in place and I have green dots and sync across everything in the HA widget on the dashboard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I only have a single switch at this location and the current PA-440 is plugged into port 48 on my Ruckus switch. I plugged in the passive into port 47 (same config, VLANs, etc) and the port went down and with err-diabled BPDUGUARD. Is that expected? I want to cycle the port to bring it out of error state, but don't want to bork anything as it is a remote facility. Wondering if I need to set up LACP/LAG on the switch for ports 47 and 48 since they will have the same MAC address. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have verified that with 'show interface all' on both PA-440s that the MAC addresses are the same on all interfaces.&amp;nbsp;On the passive, will the ports I am using (apart from HA) be 'configured but down'? Is that expected as well? I have the passive link state set to shutdown, so I am guessing so. Any benefit or issue with changing that to auto? Want to keep the failover timing on this as low as possible. &lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 24 Feb 2025 21:35:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1221810#M123384</guid>
      <dc:creator>inSync-MarkValpreda</dc:creator>
      <dc:date>2025-02-24T21:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: When setting up HA from a stand-alone...how should I configure LAN ports on the switch? What state are links on the passive node?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1221955#M123400</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108539"&gt;@inSync-MarkValpreda&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No, it is not expected that the port go error-disable with BPDUGuard.&amp;nbsp; The NGFW does not initiate BPDUs, but it can forward them for L2/VWire interfaces.&amp;nbsp; My &lt;EM&gt;guess&lt;/EM&gt; is that the passive may still have had the default VWire configuration on it when the ports were initially plugged in.&amp;nbsp; The ports connected to the passive NGFW should be configured exactly the same as the corresponding ports connected to the active NGFW.&amp;nbsp; As long as HA is up and the configuration is synced and the NGFW is in passive state, it is safe to bring up the ports to the passive NGFW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You do not want to setup LACP on ports connected to 2 different NGFWs.&amp;nbsp; With the same config on the ports connected to active and passive, the MAC address should only show on the port connected to the active NGFW.&amp;nbsp; If you want to configure LACP with multiple ports to each NGFW, configure 1 group to 1 NGFW, and a 2nd group to the 2nd NGFW.&amp;nbsp; If you want LACP to be pre-negotiated on the passive NGFW, check the "Enable in HA Passive State" box under the AE interface.&amp;nbsp; This will require that the passive link state be set to auto also.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you asked, changing the passive link state be set to auto will speed the failover a little bit.&amp;nbsp; The ports will be up on the passive.&amp;nbsp; You should see no traffic or MAC addresses on the passive ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 18:34:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1221955#M123400</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-02-25T18:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: When setting up HA from a stand-alone...how should I configure LAN ports on the switch? What state are links on the passive node?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1221964#M123402</link>
      <description>&lt;P&gt;Good call on when the HA device was plugged in. I think it might have been in the initial state where the interfaces are in virtual wire. I will cycle that port.&lt;/P&gt;
&lt;P&gt;No LACP on the ports connected to the different NGFWs....got it! I do have another one that I am going to do where there is an AE interface plugged into two different switches in a stack. I think I have those set for passive on the switch already. &lt;/P&gt;
&lt;P&gt;Is there anything that I &lt;EM&gt;should&lt;/EM&gt; do on the switch to keep the failover time as low as possible? &lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 21:59:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1221964#M123402</guid>
      <dc:creator>inSync-MarkValpreda</dc:creator>
      <dc:date>2025-02-25T21:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: When setting up HA from a stand-alone...how should I configure LAN ports on the switch? What state are links on the passive node?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1221978#M123403</link>
      <description>&lt;P&gt;This is a good doc on HA best practices.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5ZCAS" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5ZCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to HA Timer Settings, most people use Recommended, but you want faster failover choose Aggressive.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would definitely configure Link Monitoring.&amp;nbsp; I would only configure Path Monitoring if you have redundant switches toward the ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT:&amp;nbsp; No, there is nothing else you would do on the switch.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 22:35:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1221978#M123403</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-02-26T22:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: When setting up HA from a stand-alone...how should I configure LAN ports on the switch? What state are links on the passive node?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1222068#M123417</link>
      <description>&lt;P&gt;Thanks for the info on the switch.&lt;/P&gt;
&lt;P&gt;I inherited this PA set up, so not sure where the 'link monitoring' is, or if it is set up. I just know PBF is set up for the ISP failover. &lt;/P&gt;
&lt;P&gt;No redundant switches to the ISP in this location. &lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 22:38:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1222068#M123417</guid>
      <dc:creator>inSync-MarkValpreda</dc:creator>
      <dc:date>2025-02-26T22:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: When setting up HA from a stand-alone...how should I configure LAN ports on the switch? What state are links on the passive node?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1222069#M123418</link>
      <description>&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-web-interface-help/device/device-high-availability/ha-link-and-path-monitoring" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-web-interface-help/device/device-high-availability/ha-link-and-path-monitoring&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 22:58:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/when-setting-up-ha-from-a-stand-alone-how-should-i-configure-lan/m-p/1222069#M123418</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-02-26T22:58:07Z</dc:date>
    </item>
  </channel>
</rss>

